Cannot load lookups with some meta-data
Try with local.meta that looks like this (even the file is not in the users directory):
[lookups/test_case_import.csv] owner = admin version = 6.2.1 modtime = 1422085232.405032000
#7 Updated by Luke Murphey almost 9 years ago
Steps to repro:
- Make a lookup file (with owner as nobody)
- Define meta-data to re-assign the owner (see below)
- Restart Splunk
- Attempt to edit the lookup. Note that it either doesn't load and/or backups are not stored in the correct directory.
The meta-data should look something like this:
[lookups/test_perms.csv] access = read : [ * ], write : [ admin ] export = none owner = luke
#11 Updated by Luke Murphey almost 9 years ago
This seems to be working now. The main issue occurs when the lookup file has an user as an owner but the file is in a the apps directory, not the user's directory. Basically, I'm now detecting this state and including or excluding the owner when calling save accordingly so that another lookup copy doesn't get made.